Hi Krishnan, Thanks for the information. Do you have a copy of the PDF that you mention? The link comes back as "Page cannot be found". I am interested in this because we are using Duo for 2FA. Today, we use ACS for TACACS authentication but we have a project budgeted to move to ISE this year. Our security team wants us to continue to use TACACS but then would like us to have 2FA as well for device administration.
... View more
Thanks for pointing me in the right direction. I was getting stuck on how I was able to ping and traceroute to external IP's from the 3850 switch, but not from a laptop plugged into that same switch. I'll see what hardware we have laying around and see if I can add a router into the mix.
... View more
This is what I have. The DG when plugged into the 2950 is 192.168.10.1. I have a static route on the 3850 "ip route 0.0.0.0 0.0.0.0 192.168.10.1"
From the 3850 switch I can ping 8.8.88 sourcing from any of the SVI's I have on the 3850.
... View more
I have a lab which consists of a broadband connection attached to a 2950 switch. DHCP runs from the 2950 and it works perfectly. Hosts connected to this switch can communicate with one another and access the Internet (there is a single VLAN on this switch). I need to keep this environment intact, but I need to hang another switch off of this for testing.
The new switch is a 3850. I have it running the IP services license. On this switch, I have several VLAN's and hosts are able to communicate with one another. What I can't figure out is how to get them to access the Internet. Currently, the link between the 2950 and 3850 is a trunk. From the 3850 switch, I can ping the various SVI IP addresses , and I can ping external Internet hosts. If I plug a laptop into a port configured for one of the VLAN's, I can ping the other SVI's, but I can't get out to the internet.
From the 2950 switch, I cannot ping any of the SVI IP's that are on the 3850.
... View more
I have an office where we replaced their existing switches with 3850 switches and we are using Auto QOS. Once the replacement was done, we started to see discarded traffic from our NMS. In troubleshooting the issue, I noticed on some of the trunks class-default traffic was being dropped. I compared the policies from one site to another, and they are identical. The only difference I have been able to find is that in the office where we are having the discards, none of the trunks between switches are locked to 1000/full. Can this affect QOS if they are set to auto/auto? I went through some AutoQOS info from Cisco and they don't talk about setting port speed/duplex.
Thanks.
... View more
Hi David,
We are in the process of implementing a new WAAS infrastructure and while troubleshooting an issue, SMB optimization came up. Our TAC engineer mentioned the need for AD integration for SMB v3.0. We are going to be setting that up tomorrow. From the documentation we received, it is the same setup for optimizing MAPI. We were referred to the following white paper.
http://www.cisco.com/c/dam/en/us/products/collateral/routers/wide-area-application-services-waas-software/emapi_ad_configuration.pdf
... View more
Hi,
When I attempt to upgrade a 594 AppNav controller from 5.5.3 to 6.1.1, I receive the message "UPgrade of WAVE configured as apnav-controller is not supported to WAAS -6.x"
Has anyone run into this and how did you resolve this? I was thinking I could change the device mode via CLI, upgrade it, and then change the device mode back. TAC mentioned to me that I should check to see if the BIOS and BMC hardware would need to be upgraded, but I verified the version numbers and we are at the correct version.
Thanks,
... View more
Hi Leo, Would you be able to assist me with this same issue? I am seeing a port with the following error: Dec 19 09:11:39.405: %ILPOWER-3-CONTROLLER_PORT_ERR: Controller port error, Interface Gi3/0/4: Power Controller reports Short detected
... View more
I have a six switch 3850 stack that has been in production for over a month now, and everything is running normal. Last week, hosts plugged into one of the switches stopped working, the hosts are not getting an IP address (this is access layer so PC's and phones). In addition, if I look at the MAC address table for a port, I am not seeing a MAC address. All of them are running 03.03.03SE cat3k_caa-universalk9 . I am thinking this is hardware related, only because on occasion I see the following messages in the logs: Dec 17 12:21:18.052: %IOSXE-3-PLATFORM: MEMBER: 5 process fed: : -Traceback=1#88b11e4e26f5ac75f4f2f18f023e5220 :550E7000+3B9240 ngwcutils:2AF2C000+BE94 ngwcutils:2AF2C000+DA9C pthread:2E3C2000+5DC8 Also, I have a phone in a port on this switch for troubleshooting. When I removed the service-policy from the port to rebuild the port configuration, I received this message: %FED_QOS_ERRMSG-3-QUEUE_BUFFER_HW_ERROR: MEMBER: 5 fed: Failed to allocate buffers for Gi5/0/1: code 18.
... View more
I have a 3850 switch stack (6 switches) running 03.03.03SE cat3k_caa-universalk9. This week, all of the devices in this switch logs network connectivity. When these devices are moved to another switch in the stack, they work as expected. The stack ports show ok and are connected correctly. If I look at a port where a device is connected, it shows connected, and in an up/up state. However if I look at the port for the device MAC, no MAC is present. I am guessing it is hardware related. In the logs, I see entries like this. In the last hour and half, I have seen messages similar to this three times. Dec 11 14:21:31.944: %IOSXE-3-PLATFORM: MEMBER: 5 process fed: : -Traceback=1#88b11e4e26f5ac75f4f2f18f023e5220 :546C6000+3B9240 ngwcutils:2B8A2000+BE94 ngwcutils:2B8A2000+DA9C pthread:2ED38000+5DC8
... View more
I have a stack of 7 3750x switches connected via Stackwise (one logical switch). Within this switch, I have created to powerstacks (4 switches in one, 3 in the second stack). Here is my configuration: stack-power switch 1 stack Powerstack1 standalone stack-power switch 2 stack Powerstack1 standalone stack-power switch 3 stack Powerstack1 standalone stack-power switch 4 stack Powerstack1 standalone stack-power switch 5 stack Powerstack2 standalone stack-power switch 6 stack Powerstack2 standalone stack-power switch 7 stack Powerstack2 standalone When I issue the command "Show stack-power", it looks like the stack name has changed. Before I noticed the stack name change, I noticed that all of the stack power ports were not enabled, so I went through and enabled all of them. In fact, when I first noticed those ports were not enabled, the output for "show stack-power" had many entries for different Powerstack (see second chart). Any suggestions on how to fix this? I haven't rebooted the stack yet which I have a feeling will resolve it. Power Stack Stack Stack Total Rsvd Alloc Unused Num Num Name Mode Topolgy Pwr(W) Pwr(W) Pwr(W) Pwr(W) SW PS -------------------- ------ ------- ------ ------ ------ ------ --- --- Powerstack2-5 SP-R Ring 2860 770 916 1174 3 4 Powerstack1-3 SP-R Ring 3575 772 999 1804 4 5 JAX-3750X-1501#sh stack-power Power Stack Stack Stack Total Rsvd Alloc Unused Num Num Name Mode Topolgy Pwr(W) Pwr(W) Pwr(W) Pwr(W) SW PS -------------------- ------ ------- ------ ------ ------ ------ --- --- Powerstack1-1 SP-R Stndaln 1430 760 272 398 1 2 Powerstack2 SP-R Stndaln 715 45 239 431 1 1 Powerstack2-7 SP-R Stndaln 1430 760 437 233 1 2 Powerstack2-5 SP-R Stndaln 715 45 240 430 1 1 Powerstack1 SP-R Stndaln 715 45 240 430 1 1 Powerstack1-2 SP-R Stndaln 715 45 272 398 1 1 Powerstack1-3 SP-R Stndaln 715 45 215 455 1 1
... View more
Hi, We are in the process of installing QOS Policy Manager and I am struggling with a simple way to import devices into Common Services 3.2. The interface and the documentation is lacking to say the least. If it helps, we have a separate installation of Ciscoworks LMS 4.1. If I can run an export from that and than import into Common Services, I think that would be the easiest way to get all of my devices. We use Solarwinds Orion for network monitoring, and I was hoping this application had something similar where you could do a device discovery via scanning a subnet via SNMP. If this is available, I don't see where to set this up. I did manually add a device, and I thought about exporting it and building a csv file from the headers from that file, but we have so many devices that I feel that would be very time consuming to build that list. Any suggestions?
... View more